Aggregator
SLUBStick Linux Vulnerability Let Attackers Gain Full System Control
3 months ago
Security researchers have discovered a severe vulnerability in the Linux kernel that could allow attackers to gain full control over affected systems. Dubbed “SLUBStick,” the exploit technique uses memory allocation flaws to achieve arbitrary read and write access to kernel memory. The vulnerability, detailed in a paper by Graz University of Technology researchers, affects recent […]
The post SLUBStick Linux Vulnerability Let Attackers Gain Full System Control appeared first on Cyber Security News.
Guru Baran
ИИ против CAPTCHA: Microsoft выиграла битву
3 months ago
Microsoft нейтрализовала продвинутую систему обхода CAPTCHA.
CVE-2024-36137 | Node.js File Descriptor allow-fs-write permission
3 months ago
A vulnerability classified as critical has been found in Node.js. This affects an unknown part of the component File Descriptor Handler. The manipulation of the argument allow-fs-write leads to permission issues.
This vulnerability is uniquely identified as CVE-2024-36137. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-38876 | Siemens Omnivise T3000 Application Server up to 9.2 file access (ssa-857368)
3 months ago
A vulnerability was found in Siemens Omnivise T3000 Application Server, Omnivise T3000 Domain Controller, Omnivise T3000 Product Data Management (PDM), Omnivise T3000 Terminal Server, Omnivise T3000 Thin Client and Omnivise T3000 Whitelisting Server up to 9.2. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to files or directories accessible.
This vulnerability is handled as CVE-2024-38876. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-7204 | Ai3 QbiBot up to 8.0.9.b1 Chat Box cross site scripting
3 months ago
A vulnerability was found in Ai3 QbiBot up to 8.0.9.b1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Chat Box. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-7204. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-38877 | Siemens Omnivise T3000 Application Server cleartext storage (ssa-857368)
3 months ago
A vulnerability was found in Siemens Omnivise T3000 Application Server, Omnivise T3000 Domain Controller, Omnivise T3000 Network Intrusion Detection System (NIDS), Omnivise T3000 Product Data Management (PDM), Omnivise T3000 Security Server, Omnivise T3000 Terminal Server, Omnivise T3000 Thin Client and Omnivise T3000 Whitelisting Server. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is traded as CVE-2024-38877. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-38879 | Siemens Omnivise T3000 Application Server Network Interface improper authentication (ssa-857368)
3 months ago
A vulnerability was found in Siemens Omnivise T3000 Application Server and classified as critical. This issue affects some unknown processing of the component Network Interface Handler. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2024-38879. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-38878 | Siemens Omnivise T3000 Application Server API Endpoint path traversal (ssa-857368)
3 months ago
A vulnerability has been found in Siemens Omnivise T3000 Application Server and classified as problematic. This vulnerability affects unknown code of the component API Endpoint. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-38878. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7323 | Digiwin EasyFlow .NET 5.x/6.1.x/6.6.x absolute path traversal
3 months ago
A vulnerability, which was classified as problematic, was found in Digiwin EasyFlow .NET 5.x/6.1.x/6.6.x. This affects an unknown part. The manipulation leads to absolute path traversal.
This vulnerability is uniquely identified as CVE-2024-7323. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40722 | CHANGING Information Technology TCBServiSign prior 1.0.24.0318 on Windows API stack-based overflow
3 months ago
A vulnerability, which was classified as critical, has been found in CHANGING Information Technology TCBServiSign on Windows. Affected by this issue is some unknown functionality of the component API. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-40722. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40723 | CHANGING Information Technology HWATAIServiSign prior 1.0.24.0219 on Windows API stack-based overflow
3 months ago
A vulnerability classified as critical was found in CHANGING Information Technology HWATAIServiSign on Windows. Affected by this vulnerability is an unknown functionality of the component API. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-40723. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40721 | CHANGING Information Technology TCBServiSign prior 1.0.24.0318 on Windows Remote Code Execution
3 months ago
A vulnerability classified as critical has been found in CHANGING Information Technology TCBServiSign on Windows. Affected is an unknown function. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2024-40721. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40719 | CHANGING Information Technology TCBServiSign prior 1.0.24.0318 on Windows inadequate encryption
3 months ago
A vulnerability was found in CHANGING Information Technology TCBServiSign on Windows. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to inadequate encryption strength.
The identification of this vulnerability is CVE-2024-40719. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40720 | CHANGING Information Technology TCBServiSign prior 1.0.24.0318 on Windows API Remote Code Execution
3 months ago
A vulnerability was found in CHANGING Information Technology TCBServiSign on Windows. It has been declared as critical. This vulnerability affects unknown code of the component API. The manipulation leads to Remote Code Execution.
This vulnerability was named CVE-2024-40720. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36268 | Apache InLong TubeMQ Client up to 1.12.0 code injection
3 months ago
A vulnerability was found in Apache InLong TubeMQ Client up to 1.12.0. It has been classified as critical. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2024-36268. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
每周勒索威胁摘要
3 months ago
1.Ransomhub勒索团伙公布新的受害公司
2.BianLian团伙公布新的受害公司
3.Cactus勒索团伙公布了新的受害公司
【0802】重保演习每日情报汇总
3 months ago
每日更新当天鲜活情报和热点漏洞
搜狗躺枪?详解如何通过各类输入法跳过windows锁屏
3 months ago
搜狗躺枪?详解如何通过各类输入法跳过windows锁屏
【0802】重保演习每日情报汇总
3 months ago
导语一年一度的“大考”持续火热进行中,攻防演练期间本公众号会每日更新当天鲜活情报和热点漏洞,欢迎大家对我们进行收藏和关注!【免责声明】本文档提供的信息旨在帮助网络安全专业人员更好地理解和维护业务系统的